• Koala
  • Aligator
  • Świniak Bekon
  • Papież Polak
  • Gupik
  • Głąb gołąb
  • Wąż rzeczny
  • 123456
  • ${@var_dump(md5(248004596))};
  • ${832455057+992089325}
  • /*1*/{{813557119+914165422}}
  • 123456 expr 947096801 + 987314078
  • 123456
  • 123456
  • 123456
  • '-var_dump(md5(422110125))-'
  • ${912545873+938158148}
  • 123456|expr 901670067 + 826086487
  • 123456
  • 123456$(expr 824212597 + 959832729)
  • 123456
  • 123456
  • ${(971976330+974193412)?c}
  • 123456
  • 123456&set /A 865787150+986279036
  • 123456
  • 123456
  • #set($c=943600799+881350652)${c}$c
  • 123456'and/**/extractvalue(1,concat(char(126),md5(1828935032)))and'
  • expr 943469375 + 869797091
  • 123456
  • 123456/**/and+0=0
  • <%- 840522291+811690548 %>
  • 123456"and/**/extractvalue(1,concat(char(126),md5(1983876817)))and"
  • 123456
  • 123456/**/and+0=8
  • extractvalue(1,concat(char(126),md5(1794960838)))
  • 123456'and'm'='m
  • 123456
  • 123456'and(select'1'from/**/cast(md5(1694791227)as/**/int))>'0
  • 123456'and'v'='q
  • 123456
  • 123456/**/and/**/cast(md5('1289157049')as/**/int)>0
  • 123456"and"g"="g
  • 123456
  • convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1317434289')))
  • 123456
  • 123456"and"y"="q
  • 123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1853418523')))>'0
  • 123456
  • 123456
  • 123456鎈'"\(
  • 123456
  • 123456
  • 123456'"\(
  • 123456
  • 123456
  • (select*from(select+sleep(0)union/**/select+1)a)
  • (select*from(select+sleep(2)union/**/select+1)a)
  • 123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
  • 123456'and(select*from(select+sleep(2))a/**/union/**/select+1)='
  • 123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
  • 123456"and(select*from(select+sleep(2))a/**/union/**/select+1)="
  • 123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
  • 123456/**/and(select+1/**/from/**/pg_sleep(2))>0/**/
  • 123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
  • 123456'/**/and(select'1'from/**/pg_sleep(2))::text>'0
  • 123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
  • 123456/**/and(select+1)>0waitfor/**/delay'0:0:2'/**/
  • 123456'and(select+1)>0waitfor/**/delay'0:0:0
  • 123456'and(select+1)>0waitfor/**/delay'0:0:2
  • 123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('v',0)
  • 123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('b',2)
  • 123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('h',0)='h
  • 123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('x',2)='x